CVE-2026-93991

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
19/09/2026
Last modified:
22/09/2026

Description

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec arguments, parameter values, and annotations.